CVE-2023-32629 is a local privilege-escalation vulnerability in Ubuntu-specific Linux kernel OverlayFS handling. The OverlayFS metadata copy-up path, ovl_copy_up_meta_inode_data, fails to perform required permission checks before invoking ovl_do_setxattr. An attacker able to create and manipulate an OverlayFS mount can abuse the unchecked extended-attribute operation to apply metadata in a manner not permitted by normal access controls, leading to elevated privileges. The issue can also undermine container isolation in applicable Ubuntu environments.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a minimal local privilege-escalation exploit for Ubuntu targeting CVE-2023-2640 and CVE-2023-32629, commonly referred to as GameOver(lay). The repository contains only two files: a tiny README naming the CVEs and a single Bash exploit script, exploit.sh, which is the functional entry point. The script is not a scanner or detector; it directly performs exploitation. The exploit uses a local attack vector only. It invokes unshare to create a new user/mount namespace, prepares four temporary directories (l, u, w, m), copies python3 from /usr/bin/python3 into the lower directory, applies the cap_setuid capability to that copied interpreter, mounts an overlay filesystem, and triggers the vulnerable overlay behavior with touch m/*. After the overlay manipulation, it executes the modified Python interpreter from the upper directory and calls os.setuid(0) to become root. It then copies /bin/bash to /var/tmp/bash, sets mode 4755 to make it a SUID root shell, launches /var/tmp/bash -p, and finally attempts cleanup by removing the temporary directories and the dropped shell. There are no network indicators, remote callbacks, hardcoded IPs, or URLs in the exploit logic. The main fingerprintable artifacts are local filesystem paths and temporary directories used during exploitation, especially /var/tmp/bash as the privileged shell artifact. Overall, this is a compact, operational Bash proof-of-exploit for local root escalation on vulnerable Ubuntu systems.
Repository contains a compact exploit toolkit with 3 files: a large standalone Python script (wp2shell.py), a Nuclei exposure template (wp2shell-exposure.yaml), and a README documenting usage and attack flow. The Python script is the main artifact and implements several modes: non-destructive scanning, blind SQLi validation, blind SQL data extraction, authenticated RCE using recovered admin credentials, credential-less pre-auth RCE by forging an administrator and deploying a self-cleaning webshell/plugin, root-prerequisite diagnostics, and a full Linux LPE chain. The Nuclei template is limited to detection/fingerprinting and checks the homepage, RSS feed, and REST batch route for vulnerable WordPress versions and exposed /batch/v1 behavior. The exploit targets WordPress core vulnerabilities CVE-2026-60137 (pre-auth blind SQLi via REST batch route confusion / author__not_in path) and CVE-2026-63030 (unauthenticated RCE via admin forge + webshell upload). README and script also describe optional post-exploitation privilege escalation attempts against Linux using CVE-2023-2640/CVE-2023-32629, CVE-2023-4911, and CVE-2024-1086, plus SUID/sudo fallback. Overall, this is not just a detector: it is a multi-stage operational exploit chain with customizable command execution and optional interactive shell behavior.
This repository is a small local privilege escalation PoC for Ubuntu OverlayFS vulnerabilities CVE-2023-2640 and CVE-2023-32629, not a remote exploit and not part of a larger framework. It contains three files: an MIT LICENSE, a README explaining the technique and affected systems, and a single Bash exploit script (ex.sh) that serves as the entry point. The exploit works in three stages: it clears a workspace under /tmp, enters a temporary user/mount namespace with unshare -rm, copies /usr/bin/python3 into a lower directory, applies cap_setuid+eip to that copy, mounts an OverlayFS using lowerdir/upperdir/workdir, and touches files in the merged mount to trigger the vulnerable copy-up path. After the namespace exits, the script runs the resulting ./u/python3 from the real host context and executes Python code that calls os.setuid(0) and launches /bin/bash, yielding a true host root shell rather than a namespace-confined fake root shell. There are no network indicators or external callbacks; the exploit is entirely local and relies on filesystem paths, OverlayFS behavior, Linux capabilities, and namespace handling. The code is concise but functional, with a hardcoded payload that directly spawns a root shell, making it an operational PoC rather than a mere detection script.
This repository provides operational exploits for two major vulnerabilities: 1. **phpMyAdmin 4.8.1 RCE (CVE-2018-12613):** - The main exploit is implemented in `exploits/phpmyadmin_rce/exploit.py`, which targets phpMyAdmin 4.8.0/4.8.1 instances running on PHP < 7.3. The exploit leverages a PHP code injection vulnerability via crafted SQL queries, allowing arbitrary command execution on the server. The script supports direct command execution and can be used to spawn a reverse shell to the attacker's machine. The repository also includes `reverse_shell.sh`, a utility to generate various reverse shell payloads in multiple languages (bash, nc, socat, php, python, perl, ruby), making it flexible for different environments. - The exploit requires valid credentials for phpMyAdmin and a vulnerable configuration (e.g., no restrictive disable_functions in PHP, and authentication type set to 'config' for local testing). The README provides detailed usage instructions and mitigation advice. 2. **GameOverlay Privilege Escalation (CVE-2023-2640, CVE-2023-32629):** - The `exploits/gameoverlay/exploit.sh` script targets specific vulnerable Linux kernel versions (5.19.0, 6.2.0, 5.4.0, mainly on Ubuntu). It exploits a flaw in OverlayFS and unprivileged user namespaces to set the SUID bit on /bin/bash, granting root shell access to a local attacker. The script checks kernel version, creates user namespaces, and manipulates overlay mounts to achieve privilege escalation. The repository is well-structured, with separate folders for exploits, mitigations (including hardening guides and configuration patches for PHP and Apache), and documentation. The main focus is on providing practical, ready-to-use exploit scripts for both remote and local attack vectors, along with guidance for mitigation and hardening. No fake or detection-only scripts are present; all code is functional and directly related to exploitation.
This repository contains a single Metasploit module: 'gameoverlay_privesc.rb', which exploits privilege escalation and container escape vulnerabilities in Ubuntu's overlayfs implementation (CVE-2023-2640 and CVE-2023-32629). The exploit targets specific Ubuntu versions (18.04, 20.04, 22.04, 22.10, 23.04) with vulnerable kernel versions (5.4.0, 5.19.0, 6.2.0). The module checks the target's OS and kernel version, then abuses overlayfs to create a setuid root binary or execute a payload as root, providing full root access or container escape. The exploit requires a writable directory (default: /tmp) and drops artifacts (such as a setuid shell in /var/tmp/<random>). The code is written in Ruby and is structured as a standard Metasploit local exploit module, supporting both binary and command payloads. The main attack vector is local privilege escalation, and the exploit is operational, providing a working root shell or arbitrary code execution as root.
This repository contains a Bash script ('gameoverlay.sh') and a README file. The script is an exploit for CVE-2023-2640 and CVE-2023-32629, targeting a privilege escalation vulnerability in OverlayFS on certain Ubuntu versions (tested on Ubuntu 20.04 with kernel 5.4.0). The exploit works by creating directories, copying the system's python3 binary, setting the setuid capability, and mounting an overlay filesystem to manipulate file permissions. It then uses the modified python3 binary to escalate privileges and execute the 'id' command as root, demonstrating successful exploitation. The attack vector is local privilege escalation, requiring execution by a non-root user on a vulnerable system. The repository is straightforward, with the main exploit logic contained in a single Bash script, and no network or remote endpoints involved.
This repository contains a proof-of-concept (POC) exploit for CVE-2023-32629 and CVE-2023-2640, which are privilege escalation vulnerabilities affecting certain versions of Ubuntu. The repository consists of a README.md describing the exploit and crediting the original author, and a single Bash script (poc.sh) that implements the exploit as a one-liner. The script uses Linux namespaces, overlay filesystems, and Python 3 to escalate privileges and spawn a root shell. The exploit is local-only and requires the attacker to have shell access to a vulnerable Ubuntu system with Python 3 installed. No network endpoints are involved; the only fingerprintable endpoints are the use of /usr/bin/python3 and /bin/bash. The repository is a simple POC and does not include detection or weaponization features.
This repository contains a local privilege escalation exploit targeting Ubuntu kernels vulnerable to CVE-2023-2640 and CVE-2023-32629. The exploit is implemented as a Bash script (exploit.sh) that leverages overlayfs extended attribute permission bypasses to escalate privileges. The script creates several directories, copies the python3 binary, sets capabilities, mounts an overlay filesystem, and uses Python to set UID to 0 (root), copy /bin/bash to /var/tmp/bash, set it as setuid-root, and spawn a root shell. After exploitation, it cleans up all created files and directories. The exploit is operational and provides a root shell on affected systems. The only code file is exploit.sh, and the repository is simple, with clear instructions in the README.md. No network endpoints are involved; all actions are local to the filesystem.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.